CVE-2018-19790
MEDIUMSymfony 2.7.0-2.7.49, 2.8.0-2.8.48, 3.0.0-3.4.19, 4.0.0-4.0.14, 4.1.0-4.1.8, 4.2.0 Open Redirect via Backslash
Title source: llmDescription
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/106249
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE/
Patch, Vendor Advisory x_refsource_confirm
https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-http
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2019/dsa-4441
Mailing List mailing-list
x_refsource_bugtraq
https://seclists.org/bugtraq/2019/May/21
Scores
CVSS v3
6.1
EPSS
0.0149
EPSS Percentile
70.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (6)
debian/debian_linux
8.0
fedoraproject/fedora
28
sensiolabs/symfony
2.7.0 - 2.7.50
symfony/security
2.7.38 - 2.7.50Packagist
symfony/security-http
2.7.38 - 2.7.50Packagist
symfony/symfony
2.7.38 - 2.7.50Packagist
Published
Dec 18, 2018
Tracked Since
Feb 18, 2026